Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA 5520 DNS Issue for Guest Network

Hi All,

I have configured ASA 5520 for 3 Networks & one ISP.

1>   Official proxy

2>   Guest ( SSID) on controller  network Office Area

3>   GueSt ( SSID) on controller Network Accomodation Area.

From accomodation area gueSt ( configured on switch through route map and hitting to internal1 Interface on firewall, i am able to access and browse the internet but not from guest office area, although able to ping all external IP's for google/yahoo but not domain name so unable to browse.

Pls. help to resolve. Config is below.

interface GigabitEthernet0/0
 description Connected to Office LAN network
 nameif internal0
 security-level 100
 ip address
interface GigabitEthernet0/1
 description Connected to GUEST network
 nameif internal1
 security-level 1
 ip address
interface GigabitEthernet0/3
 description ISP facing interface
 nameif external0
 security-level 0
 ip address

route external0 1

route internal1 1


object network obj_to_off
object network obj_to_off
 nat (internal0,external0) dynamic interface

object network obj-2-gueSt
object network obj-2-gueSt
 nat (internal1,external0) dynamic interface

object network obj-2-guest
object network obj-2-guest
 nat (internal1,external0) dynamic interface



Super Bronze

Hi, So the users connected to



So the users connected to the subnet that is directly connected to the "internal1" interface can not do DNS lookups for some reason but their external connectivity is otherwise fine?


Have you confirmed that their network settings are correct so that the traffic is forwarded to the ASA? Are the DNS servers configured correct? Where are the DNS servers located at? Have you monitored logs through ASDM while attempting connections from the problematic Guest Office network?


- Jouni

New Member

 Yes guest user x.x.25.0


Yes guest user x.x.25.0 directly connected to internal1 and gueSt x.x.249.0 user connected through internal1 from core switch through router map.

Core SW Config......

access-list 49 permit

route-map 49 permit 20
 match ip address 49
 set ip next-hop


Ans it was working fine from last two years, Y day sudden happened that x.x.249.0 users able to access internet but x.x.250.0 user not.

I am connecting my laptop to guest able to ping all external site IP like as well but not able to access not opening any page, and whenever connecting to GueSt SSID browing well.






CreatePlease login to create content